BACK TO CORTEX

TRUST

What we do with the most personal thing you own

Cortex asks for your writing, your voice, your history, and sometimes your screen. That is a lot to hand anyone. This page tells you exactly what happens to it — including the parts that are not flattering to us.

We never train on your data
Nothing you put into Cortex is used to train any model — ours or anyone else's. Your corpus builds your clone and nothing else.
Zero data retention with model providers
Every request Cortex sends to a model provider is marked no-retention, so your content is not stored on their side after the response comes back.
You can leave with everything, at any time
One button exports your entire corpus as a file you keep. One button deletes all of it, permanently.

What we collect

Only what you give us, plus what you explicitly connect:

  • Text, files, and documents you upload.
  • Voice recordings you make, and their transcripts.
  • AI chat exports and social exports you choose to import.
  • Data from accounts you connect (calendar, email), read-only, and only the capabilities shown to you at the time you connect them.
  • If you install Cortex for Mac: screen and audio context, which is opt-in, separate, and can be paused at any time.

We do not buy data about you, and we do not scrape you from the open web.

Who can see it

Your brain is private by default. New accounts are not public — your clone answers nobody until you turn it on yourself in Settings.

Here is the uncomfortable part, stated plainly:Cortex is not end-to-end encrypted, and we are not going to pretend otherwise. The whole product works by retrieving over your corpus on our servers, which means our systems can read it. Your data is encrypted in transit and at rest by our infrastructure provider, and access is restricted to a small number of people — but “we cannot see it” would be a lie, so we do not say it.

What we do instead is make every privileged access visible to you. Cortex support can repair a brain when something breaks. Every time that happens it writes a row to an append-only log that you can read in Settings → Your data. That log cannot be edited or erased from inside the product, including by the person it names.

What we send to model providers

Cortex uses OpenAI and Anthropic models to build and run your clone. Requests carry the parts of your corpus needed to answer, and every one is sent with retention disabled, so the provider does not keep your content after responding.

Your data is never used to train those models. That is true both because we do not send it for training and because the API terms of both providers prohibit it.

How long we keep it

Your corpus stays until you remove it — that is the point of a compounding brain. Voice recordings are kept so your voice clone can be rebuilt with more material over time. You can delete individual sources, or everything at once.

How to leave

Export. One file containing every source, note, memory, chat, and artifact in your brain, plus download links for your recordings. It is plain JSON — readable, and portable to anything you want to move to.

Delete. Your account locks immediately and your public clone goes offline the moment you confirm. Seven days later everything is permanently destroyed: sources, memories, chats, transcripts, recordings, your cloned voice at our voice provider, API keys, and connected accounts. The seven days exist so a moment of frustration — or someone else getting into your account — is recoverable. You can cancel any time before the deadline.

Two things survive on purpose: your username stays reserved so nobody inherits your public clone URL, and billing records are kept because they are financial records. No personal content remains.

Both live in Settings → Your data.

The provenance firewall

Cortex separates what you said from what merely happened around you. Content from third parties, ambient capture, or connected accounts can help your clone answer a question and is always attributed — but it can never merge into your own memory or shape your profile, your identity model, your judgment, or your voice.

Practically: a colleague’s opinion in an email thread you imported will never become something your clone believes. Device and connector data is also excluded entirely from your public clone, so anything ambient stays between you and your own brain.

What we are still working on

Being straight about the gaps, because you should be able to price them:

  • We do not yet hold a SOC 2 report. If you are evaluating Cortex for a company and need one, tell us — it moves up the list based on who asks.
  • Per-user encryption keys, which would narrow our own access further, are not implemented.
  • Retention controls are all-or-nothing today. Per-source retention windows are planned, not shipped.

Questions

Ask a person: aashwinsin@gmail.com. The formal legal versions are in our Privacy Policy and Terms.

v-1c7fa84